VDB
Sign up
HIGH8.8

GHSA-5f6p-4hxq-rjxm

Umbraco CMS vulnerable to CSRF

Quick fix

GHSA-5f6p-4hxq-rjxm — Umbraco.CMS: upgrade to the fixed version with the command below.

dotnet add package Umbraco.CMS --version 7.4.0

Details

Umbraco before 7.4.0 allows remote attackers to bypass anti-forgery security measures and conduct cross-site request forgery (CSRF) attacks as demonstrated by editing user account information in the `templates.asmx.cs` file.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/Umbraco.CMS
Introduced in: 0Fixed in: 7.4.0
Fixdotnet add package Umbraco.CMS --version 7.4.0

References